INTL India - Remote Splunk Engineer
Role details
Job location
Tech stack
Requirements
Strong SPL knowledge and ability to write complex searches, optimize them, and explain why they perform the way they do
-Hands-on Splunk data onboarding experience - forwarders, HEC, API inputs, props/transforms, field extractions
-CIM normalization - understanding of the data models, you know how to validate compliance, and you know what breaks when a source is not normalized
-Splunk Enterprise Security - correlation searches, notable events, data model acceleration
-Index management - retention policies, tiered storage, capacity planning
-Experience with Splunk ES in a security operations context, not just as a log aggregation tool -Risk-Based Alerting (RBA) implementation and tuning
-ESCU - deploying, customizing, and maintaining Splunk's detection content library
-Python - scripted inputs, custom Splunk commands, REST API integrations
-Familiarity with MITRE ATT&CK and how it maps to Splunk data sources and detection content
-Splunk Cloud administration
-Experience with CrowdStrike, Microsoft Defender, or Entra ID log sources specifically
-Splunk certifications - Splunk Core Certified Power User or above
Benefits & conditions
$10/hr to $15/hr
Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401K retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.